Frequently asked questions
Frequently asked questions privacy and security
How does my HR system link to the ArboNed Absence Portal?
If your organisation already uses an integration with the ArboNed Absence Portal, data is exchanged securely in accordance with applicable standards and security requirements. The integration uses the SIVI Absence Standard, which provides clear data definitions, process agreements, and interfaces (APIs and messaging services) for the secure and interoperable exchange of absence-related data. The availability of integrations depends on the system concerned and the agreements in place.
How is compliance with privacy legislation (GDPR) ensured?
IT&Care and its partners process personal data in accordance with applicable privacy legislation, including the General Data Protection Regulation (GDPR). Appropriate technical and organisational measures are in place to protect personal data. HumanTotalCare has appointed a Data Protection Officer (DPO) who oversees compliance with privacy legislation and regulations.
Key principles include:
- Personal data is processed only for legitimate and clearly defined purposes.
- Only the data necessary for the provision of services is processed.
- Data subjects can exercise their privacy rights, including the right to access, rectify and delete their personal data.
- Personal data is processed within a secure environment.
For more detailed information, please refer to the Privacy Regulations.
Is a processing agreement with IT&Care always necessary for a link?
A processing agreement is not required in every case. IT&Care applies the following principle:
- In the case of negative registration, whereby only data relating to employees with care needs is exchanged with the occupational health and safety service ArboNed, no processing agreement between the customer and IT&Care is required. This also applies if a technical link is used. In this situation, IT&Care does not act as your processor, but merely facilitates the exchange of data to the occupational health and safety service.
- For a positive registration, where you also share data on employees without care needs (in the ArboNed Absence Portal or via a link), a processing agreement between you, as the employer, and IT&Care is required. In this case, IT&Care processes personal data on your behalf and therefore acts as a processor.
If there is a negative registration, but you do use the ArboNed Absence Portal as part of the service, this may lead to a different situation. If you actively use the portal for your own absence registration, a processing agreement between you and IT&Care is necessary. If the portal is only used passively to consult feedback from the occupational health and safety service, this is not required.
You may not switch from negative to positive registration independently. This always requires consultation with your ArboNed account manager so that the contractual agreements can be amended and, if applicable, a processing agreement can be concluded with IT&Care.
How is my customer data protected from other customers in a multi-tenant platform on a technical level?
Customer data is logically separated in the underlying database structure. Each customer has their own, protected dataset, which means that your data remains strictly separated from the data of other customers. IT&Care manages database encryption and key storage centrally; use of customer-managed keys does not apply. In addition, the database environment is actively hardened and secured according to best practices, ensuring data integrity and confidentiality within the multi-tenant architecture.
Where is my data hosted and stored?
All data processed in the ArboNed Absence Portal is stored in the Microsoft Azure cloud environment. These cloud servers are located physically in the Netherlands, which means that your data remains within the Netherlands and the European Economic Area (EEA). Microsoft Azure meets strict requirements for data residency and compliance. The Azure data centres offer a robust, modern infrastructure with high availability, security and disaster recovery capabilities. The Azure environment for IT&Care is designed in such a way that only authorised parties (IT&Care and BlueVi B.V.) have access. This guarantees that your customer data is securely hosted under the supervision of IT&Care in the Dutch Azure region, in accordance with all relevant laws and regulations.
What happens in the event of a data breach or security incident?
Both IT&Care and BlueVi have clear procedures for incident and data breach management. Safety and transparency are paramount in this regard. This includes:
Incident detection: Our IT environment is monitored 24/7 for suspicious activity or vulnerabilities. IT&Care has set up real-time monitoring and keeps a constant eye on the infrastructure. The internal Security Operations team uses NIDS, XDR, SIEM and SOAR technologies, supported by an external Managed Detection & Response provider affiliated with Z Cert, which also offers DFIR services.
Incident response plan: In the unlikely event of a security incident or data breach, an incident response plan will be immediately implemented. Authorised security and privacy officers from IT&Care and BlueVi B.V. then work together to plug the leak, limit the impact and prevent a recurrence. In doing so, they act strictly in accordance with the law, contractual agreements and internal procedures.
Reporting obligation and communication: In accordance with the GDPR and the data breach reporting obligation, IT&Care will inform you as soon as possible if your data has been affected by a serious data breach. You will then receive information about the nature of the leak, what data is involved, the (expected) impact and the measures being taken. As you are the data controller, you are obliged to report the data breach to the Information Commissioner's Office (ICO) if it is reportable and, if applicable, to inform the individuals concerned. IT&Care will support you in this by providing the necessary information in a timely and comprehensive manner, as stipulated in the processing agreement. We always strive for transparency and due diligence in such situations.
Continuous improvement: After resolving major incidents, we conduct an evaluation. Where necessary, we improve our security measures and processes to prevent any future incidents.
Thanks to our detection technologies, proactive approach and rapid response capacity, we are able to effectively manage incidents. Of course, we do everything in our power to prevent data breaches. Should such a breach occur, you will be informed appropriately and in a timely manner, and the necessary steps will be taken to protect your data.What information security and privacy certifications do IT&Care and its partners hold?
Both IT&Care and BlueVi B.V. have leading certifications that demonstrate their compliance with high standards for information security and privacy:
IT&Care B.V.: ISO/IEC 27001 and NEN 7510 certified. This means that IT&Care meets the highest requirements for process control and protection of medical and personal data. IT&Care is also registered with the Personal Data Authority as a processor.
BlueVi B.V.: ISO/IEC 27001 and NEN 7510 certified for the ArboNed Absence Portal. In addition, BlueVi B.V. has an ISAE 3000 Type II assurance statement, in which the most important privacy controls are independently assessed on an annual basis.
These certifications are verified annually by external auditors, confirming that all parties continuously work according to strict security standards and legislation.
Here are the links to our certifications:
What logging is available and how is logging organised?
What logging is available and how is logging organised?
In principle, you have limited direct access to logging from our systems. For this reason, we recommend using single sign-on (SSO) wherever possible, so that logging and user management can be largely handled within your own IT environment. IT&Care logs all relevant access and processing of personal data in accordance with the NEN 7513 standard. In the event of a security incident, we will provide you with the necessary log data if this is relevant for the investigation or for accountability purposes.
Who has access to my data?
Access to your data is strictly limited to authorised persons and is done on a need-to-know basis. In practice, this means that only authorised users can access your data:
IT administrators (IT&Care): A limited number of IT administrators at IT&Care have access to the systems for maintenance and support. This access is strictly regulated and logged in accordance with the NEN 7510 and NEN 7513 standards. These IT&Care employees treat all personal data, including medical data, as confidential. These IT&Care employees have signed a confidentiality agreement.
BlueVi B.V. support: Employees of BlueVi B.V. do not have standard access to customer data. In exceptional cases, such as for technical support or incident handling, temporary access may be required. This only happens with the consent of IT&Care and under strict conditions in accordance with the processing agreement.
No external party or unauthorised person can access your data. The roles and rights within the ArboNed Absence Portal are designed so that each user only sees the information relevant to his/her role. This ensures that privacy and confidentiality are maintained.
Who processes my data when I use the ArboNed Absence Portal and what are their roles?
You are the data controller for your own data. This means that, as an employer, you determine which data is processed and for what purpose, for example in the context of case management. If you use this absence portal, you have appointed IT&Care as a processor. In introducing the new absence portal, IT&Care is using the software and services of BlueVi B.V. (the supplier of the absence portal) as a sub-processor. A sub-processor agreement has been concluded with BlueVi B.V., which stipulates that they may only process your data in accordance with the instructions of the controller and that they must take appropriate security measures. IT&Care and BlueVi B.V. therefore work together to keep your data secure and confidential, each within their own role and responsibility.
Invoicing
Will anything change regarding invoicing?
The existing arrangements will continue. However, we will be using a different system, which means that invoices will have a different layout.
Is it possible to send customers a paper invoice?
No, we only issue digital invoices.
Why have I received two invoices?
In the month in which your organisation moves to the new system, you may receive two invoices on a one-off basis:
- One invoice from the current system for subscription charges and services provided up to the migration date.
- One invoice from the new system for services provided from the migration date until the end of the month.
After that, you will receive your invoices from the new system in a different format. Of course, you will only receive an invoice if services have actually been provided.
Logging in
How do you create a password?
You log in to the ArboNed Absence Portal via the ArboNed Employability Portal. Instructions on how to create your password can be found in the dedicated ‘Logging in to the Employability Portal’ guide on this page.
Are default passwords used when accounts are created in the new absence portal, and how is the security of the login process ensured?
The primary user can create new accounts for other users and assign the appropriate roles and permissions.
Once an account has been created, the relevant employee will receive an email. The employee then creates their own password. This password must meet a number of requirements. After the password has been created, verification takes place using an authenticator. Once verification is complete, you can log in using your username and password.
What happens if you do not activate your account in time, within 72 hours?
If the link has expired, you can contact us and ask us to create a new account. The relevant email address is provided in the activation email.
Why do I receive a registration invitation in Dutch if I am an English-speaking user?
The registration invitation is always sent in Dutch. Once you select the invitation and complete the registration process, you can choose either Dutch or English. From that point onwards, you will receive further communications in your chosen language.
You can also set your language on the login screen. You can change your language preference in the Employability Portal at any time.
Could my organisation’s IT security block emails from the absence portal or block the URL?
We do not expect this to happen. However, we recommend asking your IT department to add the following websites and email address to its allowlist:
https://www.inzetbaarheidsportaal.nl
https://www.inzetbaarheidsportaal.nl/welcome
https://arboned.inzetbaarheidsportaal.nl (domain)
Inloggen@inzetbaarheidsportaal.nl
Other
What will happen to my existing data?
You can find relevant questions about data, privacy and security in our Trust Centre at arboned.nl/en/trust-centre.
Technical
As an ArboNed customer, do you need to make any changes to your existing integrations because of the move to the new portal?
No. The move to the new portal will not affect existing integrations. They will continue to operate without any changes. You do not need to take any action. For most customers, no technical changes or additional discussions will be required either.
What does the move to the new system mean for our existing integration?
As a customer, you are not expected to experience any noticeable impact. The integration does not need to be modified and its connection will remain unchanged.
The system
When will the new ArboNed Absence Portal go live?
Our customers will move to the new portal in phases over the coming months. We will inform you in good time, at least two weeks before the transition, when this applies to your organisation.
Do I need to prepare anything?
Make sure that your details are up to date in the systems and close the accounts of employees who have left your organisation.
How do I deactivate a user in Vandaag?
- In Vandaag, go to Settings.
- Select User management.
- Select the user you want to deactivate.
- Select Edit user.
- Enter the end date in the Valid until field. This date may also be in the past.
- Save the change.
After the end date entered, the user will no longer have access to Vandaag and will not be transferred to the ArboNed Absence Portal.Are instructional resources available?
When your organisation moves to the new portal, instructional resources will become available on this instruction page.
Which communication preferences can I set in the ArboNed Absence Portal?
In the ArboNed Absence Portal, you can choose how you would like to receive messages from ArboNed. You can choose between email and telephone.
Do you currently have written communication by post or fax selected as your preference in Vandaag? Please note that these options will no longer be available in the ArboNed Absence Portal. In this case, your communication preference will be changed to email.
What functional changes can I expect?
Possible functional changes include:
- Changes to appointment and/or document codes.
- The use of a different account or password to access the customer portal.